
The Solar Energy Industries Association (SEIA) has called for stronger cybersecurity measures across the US solar and energy storage industry in a report arguing that expanding domestic manufacturing and improving cyber resilience must go hand in hand as renewables capacity continues to grow.
The report, titled ‘Cybersecurity Priorities for America’s Solar & Storage Industry’, comes as US inverter manufacturing capacity has nearly tripled since the end of 2024, with a new production facility opened by EPC Power in July pushing the country into a tie for the world’s second-largest inverter manufacturing base.
Try Premium for just $1
- Full premium access for the first month at only $1
- Converts to an annual rate after 30 days unless cancelled
- Cancel anytime during the trial period
Premium Benefits
- Expert industry analysis and interviews
- Digital access to PV Tech Power journal
- Exclusive event discounts
Or get the full Premium subscription right away
Or continue reading this article for free
SEIA said the rapid expansion of solar and storage, which accounted for nearly 80% of new US power generation capacity additions in 2025, increases the importance of securing systems against cyber threats targeting critical infrastructure.
Tim Pawlenty, president and CEO of SEIA, said: “As solar and storage continue to lead the way in adding new power capacity to the grid, cybersecurity must remain front and centre. From secure and resilient systems to expanding domestic manufacturing, this report lays out the actions our industry is taking to strengthen US energy security, protect critical infrastructure and stay ahead of emerging threats.”
Domestic manufacturing linked to cyber resilience
According to the report, US inverter manufacturing capacity has reached 55GWac following recent factory expansions. The expansion comes as US policymakers increasingly scrutinise foreign-made inverters over potential cybersecurity risks.
SEIA argues that strengthening US-based production of key technologies, including inverters, will improve supply chain resilience, increase transparency and reduce dependence on potentially vulnerable overseas supply chains.
The report identifies three priorities for improving cybersecurity across the solar and storage sector:
- Expanding domestic manufacturing through resilient supply chains, greater supplier transparency and trusted manufacturing capacity.
- Establishing consistent baseline cybersecurity practices, including national guidance for distributed energy resources (DERs).
- Improving threat intelligence sharing and industry coordination to strengthen risk awareness and response capabilities.
Distributed energy remains a challenge
While large utility-scale solar plants connected to the bulk power system are subject to North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards, SEIA notes that most distributed solar and storage assets remain outside mandatory federal cybersecurity requirements.
The association warns that the rapid growth of internet-connected distributed energy resources, virtual power plants and remote monitoring systems creates additional cyber risks that require more consistent security standards.
SEIA is advocating for national cybersecurity guidance for distributed energy resources, building on existing frameworks developed by the US Department of Energy, NIST, IEEE and other standards bodies.
AI and the evolving regulatory landscape
Beyond traditional cyber threats, the report identifies supply chain security, third-party vendors and artificial intelligence as emerging areas of concern.
SEIA said reliance on cloud platforms, telecommunications providers, fleet management software and managed service providers expands the industry’s attack surface, requiring stronger vendor risk management throughout the lifecycle of solar and storage projects.
The report also warns that while AI can improve threat detection and operational efficiency, it may also enable attackers to identify and exploit vulnerabilities more quickly if deployed insecurely.
As previously reported in our sister journal, PV Tech Power, industry analysts have warned that AI-enabled asset management and optimisation tools could introduce new cybersecurity and operational risks for solar and storage portfolios [subscription required].
SEIA notes that the regulatory framework for utility-scale projects is becoming more stringent as NERC expands reliability requirements to cover more inverter-based resources.
However, it argues that distribution-connected solar and storage systems continue to rely largely on voluntary standards, resulting in inconsistent cybersecurity practices across the sector.
The association said it will continue working with industry, utilities and government agencies to help members navigate evolving compliance requirements while promoting proactive cybersecurity measures ahead of future regulatory mandates.